Apple tightens full disk access on mac over ai agent risks
Apple said Friday it is adding new restrictions to the "Full Disk Access" permission in macOS, responding to risks created by AI agents. The company said the update is meant to ensure that users who genuinely want to grant an application that level of access can do so only through an explicit, deliberate action on their part. The move comes weeks after Jason Aten of Inc reported that Muse, Meta's chatbot, knew the contents of his messages even though he had not given explicit permission for it to access them on either iPhone or Mac.
Meta spokesperson Andy Stone denied the account, saying message access is "entirely opt-in." For Muse to read message content, Stone said, a user must enable both Full Disk Access and the Messages connector — two separate steps. Apple did not address the Meta case directly but said certain developers are exploiting the broad permission in ways that could put users at risk, exposing files, email, messages and browsing history without the user fully understanding what they are approving.
Full Disk Access gives an application access to the user's entire system. Apple explains that the feature "largely bypasses" the regular privacy controls macOS provides, a design intended to let backup apps function properly. The problem, the company said, is that the mechanism has remained open to far wider use than backups, and as AI agents grow more autonomous and capable, the risk tied to such access increases substantially.
Apple did not provide a release date for the update, nor did it detail what the required "explicit action" will look like. The company did not respond to a request for comment from The Verge. In the meantime, users who want to limit their exposure can check privacy settings to see which apps hold the permission and revoke it where it is not needed.